• Title/Summary/Keyword: Security Rules

Search Result 329, Processing Time 0.022 seconds

Unknown Threats Detection by Using Incremental Knowledge Acquisition (상황 지식 축적에 의한 알려지지 않은 위협의 검출)

  • Park, Gil-Cheol;Cooke, Hamid B. M.;Kim, Yang-Sok;Kang, Byeong-Ho;Youk, Sang-Jo;Lee, Geuk
    • Convergence Security Journal
    • /
    • v.7 no.1
    • /
    • pp.19-27
    • /
    • 2007
  • Detecting unknown threats is a paradox ; how do you detect a threat if it is not known to exist? The answer is that unknown threat detection is the process of making a previously unknown threat identifiable in the shortest possible time frame. This paper examines the possibility of creating an unknown threat detection mechanism that security experts can use for developing a flexible protection system for networks. A system that allows the detection of unknown threats through monitoring system and the incorporation of dynamic and flexible logics with situational knowledge is described as well as the mechanisms used to develop such a system is illustrated. The system not only allows the detection of new threats but does so in a fast and efficient manner to increase the available time for responding to these threats.

  • PDF

Study on Dynamic Trust-based Access Control in Online Social Network Environment (소셜 네트워크 환경에서 동적 신뢰 중심의 접근 제어 모델에 관한 연구)

  • Baek, Seungsoo;Kim, Seungjoo
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.23 no.6
    • /
    • pp.1025-1035
    • /
    • 2013
  • There has been an explosive increase in the population of OSN(online social network) for 10 years. OSN provides users with many opportunities to have communication among friends, families and goes so far as to make relationships among unknown people having similar belief or interest. However, OSN also produced adverse effects such as privacy breaches, leaking uncontrolled information or disseminating false information. Access control models such as MAC, DAC, RBAC are applied to the OSN to control those problems but those models in OSN are not fit in dynamic OSN environment because user's acts in OSN are unpredictable and static access control imposes burden on users to change access control rules one by one. This paper proposes the dynamic trust-based access control to solve the problems of traditional static access control in OSN.

A Three-Layered Ontology View Security Model for Access Control of RDF Ontology (RDF 온톨로지 접근 제어를 위한 3 계층 온톨로지 뷰 보안 모델)

  • Jeong, Dong-Won;Jing, Yixin;Baik, Dook-Kwon
    • Journal of KIISE:Databases
    • /
    • v.35 no.1
    • /
    • pp.29-43
    • /
    • 2008
  • Although RDF ontologies might be expressed in XML tree model, existing methods for protection of XML documents are not suitable for securing RDF ontologies. The graph style and inference feature of RDF demands a new security model development. Driven by this goal, this paper proposes a new query-oriented model for the RDF ontology access control. The proposed model rewrites a user query using a three-layered ontology view. The proposal resolves the problem that the existing approaches should generate inference models depending on inference rules. Accessible ontology concepts and instances which a user can visit are defined as ontology views, and the inference view defined for controling an inference query enables a controlled inference capability for the user. This paper defines the three-layered view and describes algorithms for query rewriting according to the views. An implemented prototype with its system architecture is shown. Finally, the experiment and comparative evaluation result of the proposal and the previous approach is described.

A Review on Smart Two Wheeler Helmet with Safety System Using Internet of Things

  • Ilanchezhian, P;Shanmugaraja, P;Thangaraj, K;Aldo Stalin, JL;Vasanthi, S
    • International Journal of Computer Science & Network Security
    • /
    • v.21 no.6
    • /
    • pp.11-16
    • /
    • 2021
  • At the present time, the number of accidents has enlarged speedily and in country like India per day there are about 204 accidents occurred. Accidents of two-wheeler compose a foremost segment of every accident and it can be true for the reason that two-wheelers like bikes not able to produce as many as security measurements normally incorporated in cars, truks and bus etc. General main rootcost of the two-wheeler accidents happen only when people community not remember to wearing a device helmet and during the driving time feels like sleep condition, alcohol disbursement, many of the drivers doesn't know heavy vehicles like Loory and buses approaching into very closer to their two wheelers, contravention of two wheelers in traffic rules and regulations. Let's overcome the above situations; our important objective is to develop an intelligent system device that can successfully facilitate in avoidance of every kind of problems. Suppose any of the above stated situations occurs, at that moment how system device identify and represents the commanders and community, and finally the stated situation be able to taken care of straight away without any further delay. A smart intelligent helmet system is a defending head covering used by rider for making bike riding safer than earlier. This is finished by incorporating sophisticated features like detecting the usage of helmet by the rider, connected Bluetooth module in helmet. In order to maintain the temperature inside the helmet device we need to include CPU fan module inside the device. RF based helmet prevents road accidents and identify whether people community is not using a component helmet or used. Main responsibility of the system is to detect accidents by vibration sensors, accelerometers and also with the help of modules global positioning system and global system for mobile commnicaiton module. A wireless communication device used to discover the accident area site location and likewise notifying the two-wheeler drived people's relatives and short message text information passed to the positioned hospitals.

A Study on the Improvement of Cybersecurity Training System in Nuclear Facilities (원자력 시설 사이버보안 훈련체계 개선 방안 연구)

  • Kim, Hyun-hee;Lee, Daesung
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2022.05a
    • /
    • pp.187-188
    • /
    • 2022
  • As information processing technology develops with the trend of the times, the possibility of cyber threats to nuclear facilities is increasing. In the 2000s, there was a growing perception that cyberattacks on nuclear facilities were needed, and in fact, a cybersecurity regulatory system for nuclear power plants began to be established to prepare for cyberattacks. In Korea, in order to prepare for cyber threats, in 2013 and 2014, the Act on Protection and Radiation Disaster Prevention, Enforcement Decree, and Enforcement Rules of Nuclear Facilities, etc., and notices related to the Radioactive Disaster Prevention Act were revised. In 2015, domestic nuclear operators prepared information system security regulations for each facility in accordance with the revised laws and received approval from the Nuclear Safety Commission for implementation of information system security regulations divided into seven stages. In 2019, a special inspection for step-by-step implementation was completed, and since 2019, the cybersecurity system of operators has been continuously inspected through regular inspections. In this paper, we present some measures to build improved training to suit the steadily revised inspection of the nuclear facility cybersecurity system to counter cyber threats to the ever-evolving nuclear facilities.

  • PDF

A DRM Framework for Distributing Digital Contents through the Internet

  • Lee, Jun-Seok;Hwang, Seong-Oun;Jeong, Sang-Won;Yoon, Ki-Song;Park, Chang-Soon;Ryou, Jae-Cheol
    • ETRI Journal
    • /
    • v.25 no.6
    • /
    • pp.423-436
    • /
    • 2003
  • This paper describes our design of a contents distribution framework that supports transparent distribution of digital contents on the Internet as well as copyright protection of participants in the contents distribution value chain. Copyright protection must ensure that participants in the distribution channel get the royalties due to them and that purchasers use the contents according to usage rules. It must also prevent illegal draining of digital contents. To design a contents distribution framework satisfying the above requirements, we first present four digital contents distribution models. On the basis of the suggested distribution models, we designed a contract system for distribution of royalties among participants in the contents distribution channel, a license mechanism for enforcement of contents usage to purchasers, and both a packaging mechanism and a secure client system for prevention of illegal draining of digital contents.

  • PDF

Collaborative Governance, Decent Work and Innovation: An Analytical Framework for Sustainable Workplaces Based on the Case of Philippine Science and Technology Parks

  • SALE, Jonathan
    • World Technopolis Review
    • /
    • v.5 no.1
    • /
    • pp.71-82
    • /
    • 2016
  • This paper explores, explains and describes a framework for analyzing collaborative governance, decent work and innovation as fundamental elements of sustainable workplaces through case study of Philippine science and technology (S & T) parks. Rules, or the legal infrastructure, are particularly significant considerations that facilitate or hinder collaboration. Industrial relations/human resource (IR/HR) practices are essential to collaboration and decent work. Employee consultation and labor-management council or committee are examples of IR/HR practices that might contribute to collaboration and decent work in firms and workplaces in S & T parks as they are team approaches to production, too. Collaboration and decent work enhance the capacity to innovate. In the long run, collaborative governance, decent work and innovation tend to converge in the concept of sustainable development. The interdependencies and interactions among collaborative governance, decent work and capacity to innovate in firms operating in S & T parks make possible new solutions to new problems (i.e., innovation) and, thus, sustainable workplaces.

A Study on the Liability Risk of Air Cargo Carrier (항공화물운송인의 책임부담위험에 관한 연구)

  • Kwak, Bong-Hwan;Kang, Dong-Yoon;Ham, Young-Jin
    • International Commerce and Information Review
    • /
    • v.12 no.2
    • /
    • pp.385-405
    • /
    • 2010
  • The purpose of this study is to investigate liability risk of air cargo carrier and suggests ideas for solving problems which could be happen to air transporters on the future. because of Air transport remains one of the world's fastest growing and most important industries. And important treaties and contracts specifying transporters' responsibility regarding big scale aircraft accidents are such as Warsaw Convention in 1929, Hague Protocol in 1955, Montreal Convention in 1999. The Montreal Convention, formally the Convention for the Unification of Certain Rules for International Carriage, is a treaty adopted by Diplomatic meeting of ICAO member states in 1999. It amended important provisions of the Warsaw Convention's concerning compensation for the victims of air disasters. In conclusion, suggests to the method of air cargo security and cargo legal liability insurance which is for air cargo carrier's risk management.

  • PDF

A Study on the Comparison of the Basic Law on Electronic Commerce and the UETA (전자거래기본법과 통일전자거래법(UETA)의 비교)

  • Jeon, Soon-Hwan
    • The Journal of Information Technology
    • /
    • v.8 no.2
    • /
    • pp.135-148
    • /
    • 2005
  • The purpose of this article is to study on the Comparison of the Basic Law on Electronic Commerce and the Uniform Electronic Transactions Act(UETA). The purpose of th Basic Law on Electronic Commerce is to contribute to the national economy by clarifying the legal effect of transactions by means of electronic messages so as to ensure the security and reliability thereof and to secure fair trade, and further by establishing sound and orderly transactions, and promoting electronic commerce. It is important to understand that the purpose of the UETA is to remove barriers to electronic commerce by validating and effectuating electronic records and signatures. It is not a general contracting-the substantive rules of contracts remain unaffected by UETA. Nor is a digital signature statute. To the extent that a State has a Digital Signature Law, the UETA is designed to support and compliment that statute.

  • PDF

Implementing Balanced Scorecard with System Dynamics Approach

  • Yoon, Joseph Y. K.
    • Proceedings of the Korean Operations and Management Science Society Conference
    • /
    • 2000.04a
    • /
    • pp.330-336
    • /
    • 2000
  • This paper discusses the potential of system dynamics modelling to support balanced scorecard. The balanced scorecard is a conceptual framework for translating an organisation's strategy into a set of performance indicators. These performance indicators are distributed across the 'classic'model's four perspective: Customers, Internal Business Processes, Financial, and Learning and Growth. This balanced scorecard, whilst having significant strength, suffers from the limitation of all performance indicator systems, namely that the interrelationships between indicators are overlooked and there is no way of taking into account the impact of delayed feedback which flows from introduction of new policy and legislative changes. System Dynamics is a methodology for understanding complex problems where there is dynamic behaviour and where feedback impacts significantly on system outcomes. System dynamics provides a rigorous basis for qualitative testing of the effects of performance indicators in complex environments such as health or social security. This can be supplemented with quantitative system dynamics simulation tools that further test the validity of indicators and the business rules implicit in them. System dynamics modelling has an important role to play in extending feedback cycle in performance measurements to a full systems approach.

  • PDF